Skip to content

[Preset]: Update Architecture Governance to v0.6.2 #4906

Description

@hindermath

Preset ID

architecture-governance

Preset Name

Architecture Governance

Version

0.6.2

Description

Adds secure architecture, STRIDE/CAPEC threat models, arc42, S-ADRs, Zero Trust, SAMM, C3A/C5 cloud assurance, and audit-ready evidence to Spec Kit.

Author

Thorsten Hindermann

Repository URL

https://github.com/hindermath/spec-kit-preset-architecture-governance

Download URL

https://github.com/hindermath/spec-kit-preset-architecture-governance/archive/refs/tags/v0.6.2.zip

Documentation URL

https://github.com/hindermath/spec-kit-preset-architecture-governance/blob/v0.6.2/README.md

License

MIT

Required Spec Kit Version

=0.8.0

Required Extensions (optional)

None

Templates Provided

  • architecture-governance-model-routing
  • constitution-template
  • spec-template
  • plan-template
  • tasks-template
  • architecture-agent-guidance-addendum-template
  • threat-model-template
  • adr-template
  • arc42-security-template
  • security-quality-scenarios-template
  • zero-trust-applicability-template
  • samm-assessment-template
  • cloud-autonomy-applicability-template
  • c3a-criteria-catalog
  • cloud-compliance-assurance-template

Commands Provided

  • speckit.specify
  • speckit.plan
  • speckit.tasks

Number of Scripts (optional)

0

Tags

architecture, governance, threat-modeling, c3a, c5

Key Features

  • Update the existing catalog entry from v0.5.2 to v0.6.2; preserve preset ID and priority 20. This is not a new preset.
  • Secure architecture: STRIDE/CIA/CAPEC threat modeling, security ADRs, arc42 cross-cutting concepts, quality scenarios, Zero Trust applicability and SAMM assessment.
  • Includes the v0.6.0 BSI C3A/C5 cloud-assurance additions, with a source-bound C3A criterion catalog and distinct C5 Type 1/Type 2 evidence semantics.
  • Includes v0.6.1 privacy/data-flow, AI-tool-boundary and resilience/recovery/exit architecture integration. Regulatory applicability remains project-owned; Security Governance records or equivalent evidence can be referenced without a hard preset dependency.
  • v0.6.2 itself only corrects the release installation documentation, shortens manifest metadata and adds regression coverage. Architecture templates, command wrappers, model routing and normative cloud/regulatory content are unchanged from v0.6.1.
  • No automatic legal applicability, product acceptance, provider attestation, C5, conformity or certification claims.

Testing Checklist

  • Preset installs successfully via specify preset add
  • Template resolution works correctly after installation
  • Documentation is complete and accurate
  • Tested on at least one real project

Submission Requirements

  • Valid preset.yml manifest included
  • Linked README explains this preset and includes a valid specify preset add --from command using the exact Download URL
  • LICENSE file included
  • GitHub release created with version tag
  • Preset ID follows naming conventions (lowercase-with-hyphens)

Immutable package and validation evidence

  • Stable v0.6.2 release and validation notes, including source-inventory SPDX SBOM.
  • SHA-256 of the exact Download URL above: ebea0ede13e6d72b8d65ae56b08ae28e07b3814aca3f8e9563b6590d0c88a082.
  • Source PR #9: tested head 84c7457d9a5aa4e20b013daa578517d7b65d2e59, merge/tag commit 017e91a24a685e23f176e98c07c9ac8d81487cbb; identical source tree 68b2fed8f12b1d52ab38bc2651af79f38865925c.
  • All three native platform checks passed: macOS, Linux and Windows. Six contract tests cover the cloud catalog, boundaries, manifest/wrappers and exact one-line installation, including LF/CRLF and negative regression cases.
  • Exact tag-archive installation was verified in a disposable copy of Home Baseline's tracked .specify project context at b11f86ed40de7d5bce6ac3d768f47b33d34dfa8b, replacing Architecture only inside that temporary copy. Preset list confirms v0.6.2 at priority 20; both cloud-autonomy-applicability-template and cloud-compliance-assurance-template resolve to this version. The live project and runtime were not changed.
  • The README installation command is a single line and uses the exact submitted URL. The tag ZIP and attached release ZIP have identical extracted source trees; their distinct container hashes are documented in the release notes.
  • Existing v0.6.1 tag and archive remain unchanged; its tag ZIP SHA-256 is 9ea0721e9475e4e955c4b71214adcc96b117ef97f977115446128bd157ed05c6.
  • This submission is separate from central source-lock, Home Runtime, pilot and fleet rollout changes. No such rollout is claimed.

Activity

  1. github-actions commented on Oct 9, 2026

    @github-actions
    Contributor

    cc @github/spec-kit-maintainers — new catalog submission for review.

  2. github-actions commented on Oct 9, 2026

    @github-actions
    Contributor

    Pull request created: #4907

    Generated by Add Community Preset from Issue Submission · copilot · gpt52codex · 3.99 AIC · ⌖ 0.753 AIC · ⊞ 26.7K

  3. mnriem commented on Oct 9, 2026

    @mnriem
    Collaborator

    Thank you!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions